Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0287

Опубликовано: 19 мар. 2013
Источник: redhat
CVSS2: 4.9
EPSS Низкий

Описание

The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sssdNot affected
Red Hat Enterprise Linux 6sssdFixedRHSA-2013:066319.03.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=910938sssd: simple access provider flaw prevents intended ACL use when client to an AD provider

EPSS

Процентиль: 63%
0.00464
Низкий

4.9 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.

nvd
больше 12 лет назад

The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.

debian
больше 12 лет назад

The Simple Access Provider in System Security Services Daemon (SSSD) 1 ...

github
больше 3 лет назад

The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.

oracle-oval
больше 12 лет назад

ELSA-2013-0663: sssd security and bug fix update (MODERATE)

EPSS

Процентиль: 63%
0.00464
Низкий

4.9 Medium

CVSS2